⤷ Title: Hack TheBox Walkthrough: Fawn
════════════════════════
𐀪 Author: Eliyauergas
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:50:24 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #hackthebox_writeup
════════════════════════
𐀪 Author: Eliyauergas
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:50:24 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #hackthebox_writeup
Medium
Hack TheBox Walkthrough: Fawn
Step 1: Basic Information & Knowledge Questions
⤷ Title: HACKVISER — WEB UYGULAMA GÜVENLİĞİ
════════════════════════
𐀪 Author: Yusuf Tayip Yıldırım
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:02:42 GMT
════════════════════════
⌗ Tags: #hackviser #sql_injection #web3 #web_penetration_testing #sql
════════════════════════
𐀪 Author: Yusuf Tayip Yıldırım
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:02:42 GMT
════════════════════════
⌗ Tags: #hackviser #sql_injection #web3 #web_penetration_testing #sql
Medium
HACKVISER — WEB UYGULAMA GÜVENLİĞİ
SQL INJECTION
⤷ Title: Critical Laravel Vulnerability: 260,000+ APP_KEYs Leaked, Enabling Remote Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:18:08 +0000
════════════════════════
⌗ Tags: #Vulnerability #APP_KEY #CVE_2024_55556 #cybersecurity #data leak #Github #Laravel #PHP #RCE #vulnerability #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:18:08 +0000
════════════════════════
⌗ Tags: #Vulnerability #APP_KEY #CVE_2024_55556 #cybersecurity #data leak #Github #Laravel #PHP #RCE #vulnerability #web security
Penetration Testing Tools
Critical Laravel Vulnerability: 260,000+ APP_KEYs Leaked, Enabling Remote Code Execution
Over 260,000 Laravel APP_KEYs have been exposed on GitHub, creating a critical RCE vulnerability (CVE-2024-55556) in potentially 600+ web apps. Rotate keys now!
⤷ Title: Critical FortiWeb SQL Injection (CVE-2025-25257) Allows Remote Code Execution, PoC Published
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_25257 #cybersecurity #Fortinet #FortiWeb #Patch #RCE #security update #SQL injection #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_25257 #cybersecurity #Fortinet #FortiWeb #Patch #RCE #security update #SQL injection #vulnerability
Penetration Testing Tools
Critical FortiWeb SQL Injection (CVE-2025-25257) Allows Remote Code Execution, PoC Published
Fortinet has patched CVE-2025-25257, a critical SQL injection vulnerability in FortiWeb (CVSS 9.6) allowing unauthenticated RCE. Update your systems now to prevent exploitation.
⤷ Title: GPUHammer: New NVIDIA Vulnerability Threatens AI Models with Data Corruption
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:11:23 +0000
════════════════════════
⌗ Tags: #Vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:11:23 +0000
════════════════════════
⌗ Tags: #Vulnerability
Penetration Testing Tools
GPUHammer: New NVIDIA Vulnerability Threatens AI Models with Data Corruption
NVIDIA warns of GPUHammer, a new RowHammer-style attack on GPUs that corrupts data and severely degrades AI model accuracy, urging ECC memory activation.
⤷ Title: $40 Million Crypto Heist: GMX Hacker Returns Funds for $5M Bounty, Dodges Legal Battle
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:08:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #blockchain #Bounty #cryptocurrency #cybercrime #DeFi #exploit #GMX #hack #Restitution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:08:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #blockchain #Bounty #cryptocurrency #cybercrime #DeFi #exploit #GMX #hack #Restitution
Penetration Testing Tools
$40 Million Crypto Heist: GMX Hacker Returns Funds for $5M Bounty, Dodges Legal Battle
A hacker returned $40.5 million of $42 million stolen from DeFi exchange GMX in exchange for a $5 million bounty, avoiding immediate prosecution.
⤷ Title: Windows 11 Gets “Quick Machine Recovery”: Microsoft’s New AI-Powered Auto-Fix for Boot Failures
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:05:06 +0000
════════════════════════
⌗ Tags: #Windows #Auto_recovery #Microsoft #QMR #Quick Machine Recovery #Tech Update #Windows 11 #Windows Recovery Environment #WinRE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:05:06 +0000
════════════════════════
⌗ Tags: #Windows #Auto_recovery #Microsoft #QMR #Quick Machine Recovery #Tech Update #Windows 11 #Windows Recovery Environment #WinRE
Penetration Testing Tools
Windows 11 Gets "Quick Machine Recovery": Microsoft's New AI-Powered Auto-Fix for Boot Failures
Microsoft's new Quick Machine Recovery (QMR) for Windows 11 automates boot failure fixes via cloud and autonomous repair, offering a lifeline for unbootable PCs.
⤷ Title: Warning: “Free VPN for PC” on GitHub is a Trap for Lumma Stealer Spyware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:02:25 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #Github #Info_stealer #Lumma Stealer #malware #Spyware #Threat Alert #VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:02:25 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #Github #Info_stealer #Lumma Stealer #malware #Spyware #Threat Alert #VPN
Penetration Testing Tools
Warning: "Free VPN for PC" on GitHub is a Trap for Lumma Stealer Spyware
Cybercriminals are using GitHub to spread Lumma Stealer spyware disguised as "Free VPN for PC" and "Minecraft Skin." Be wary of unverified downloads!
⤷ Title: iOS 26 Beta 3: Apple Adds RCS Support, But Encryption Still Missing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:00:28 +0000
════════════════════════
⌗ Tags: #Apple #Android #cybersecurity #Encryption #end_to_end encryption #google #iOS 26 #Messages App #privacy #RCS #Rich Communication Services #Universal Profile 3.0
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:00:28 +0000
════════════════════════
⌗ Tags: #Apple #Android #cybersecurity #Encryption #end_to_end encryption #google #iOS 26 #Messages App #privacy #RCS #Rich Communication Services #Universal Profile 3.0
Penetration Testing Tools
iOS 26 Beta 3: Apple Adds RCS Support, But Encryption Still Missing
iOS 26 Beta 3 integrates RCS support but lacks end-to-end encryption for messages, leaving them exposed. Full encryption (RCS Universal Profile 3.0) is expected in future updates.
⤷ Title: Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
Daily CyberSecurity
Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
A Russian crypto developer lost $500K after installing a fraudulent "Solidity Language" extension for Cursor AI IDE from Open VSX, which deployed malware for remote access and data theft.
⤷ Title: CVE-2025-53833 (CVSS 10): Critical SSTI Flaw in LaRecipe Threatens Millions of Laravel Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:01:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_53833 #cybersecurity #Laravel #LaRecipe #php #rce #Remote Code Execution #Server Side Template Injection #ssti #Vulnerability #web framework
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:01:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_53833 #cybersecurity #Laravel #LaRecipe #php #rce #Remote Code Execution #Server Side Template Injection #ssti #Vulnerability #web framework
Daily CyberSecurity
CVE-2025-53833 (CVSS 10): Critical SSTI Flaw in LaRecipe Threatens Millions of Laravel Apps
A critical SSTI flaw (CVE-2025-53833, CVSS 10.0) in LaRecipe allows unauthenticated RCE on affected servers via template injection. Update to v2.8.1 immediately!
⤷ Title: Google Confirms Major OS Merger: Android & ChromeOS to Become a Single Unified Platform
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 01:53:48 +0000
════════════════════════
⌗ Tags: #Android #android #chromebooks #ChromeOS #Cross_Platform #google #Operating System #OS Merger #Sameer Samat #tablets #Tech News #Unification
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 01:53:48 +0000
════════════════════════
⌗ Tags: #Android #android #chromebooks #ChromeOS #Cross_Platform #google #Operating System #OS Merger #Sameer Samat #tablets #Tech News #Unification
Daily CyberSecurity
Google Confirms Major OS Merger: Android & ChromeOS to Become a Single Unified Platform
Google officially confirmed plans to unify Android and ChromeOS into a single platform, aiming for seamless cross-device experiences and streamlined development for its AI-driven future.
⤷ Title: CISA Warns of Active Exploitation of Wing FTP Server Flaw (CVE-2025-47812), CVSS 10
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:55:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:55:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
Daily CyberSecurity
CISA Warns of Active Exploitation of Wing FTP Server Flaw (CVE-2025-47812), CVSS 10
CISA adds critical Wing FTP Server RCE flaw (CVE-2025-47812, CVSS 10.0) to KEV. Actively exploited via null byte and Lua code injection; patch to 7.4.4 immediately!
⤷ Title: ImageMagick Flaw (CVE-2025-53101): Stack Buffer Overflow Allows Potential Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:38:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_53101 #cybersecurity #Image Manipulation #ImageMagick #memory corruption #open_source #rce #Remote Code Execution #Stack Buffer Overflow #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:38:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_53101 #cybersecurity #Image Manipulation #ImageMagick #memory corruption #open_source #rce #Remote Code Execution #Stack Buffer Overflow #Vulnerability
Daily CyberSecurity
ImageMagick Flaw (CVE-2025-53101): Stack Buffer Overflow Allows Potential Remote Code Execution
A flaw (CVE-2025-53101) in ImageMagick allows stack buffer overflows via filename templates, risking memory corruption and remote code execution. Patch now!
⤷ Title: XORIndex: North Korea’s Evolving Supply Chain Malware Targets npm Ecosystem Again
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:26:06 +0000
════════════════════════
⌗ Tags: #Malware #APT #BeaverTail #Contagious Interview #cryptocurrency #cybersecurity #HexEval #Infostealer #InvisibleFerret #malware #North Korea #npm #Socket #supply chain attack #XORIndex
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:26:06 +0000
════════════════════════
⌗ Tags: #Malware #APT #BeaverTail #Contagious Interview #cryptocurrency #cybersecurity #HexEval #Infostealer #InvisibleFerret #malware #North Korea #npm #Socket #supply chain attack #XORIndex
Daily CyberSecurity
XORIndex: North Korea’s Evolving Supply Chain Malware Targets npm Ecosystem Again
North Korean APTs are using XORIndex malware in a new npm supply chain attack, infiltrating developers via 67 malicious packages to steal crypto wallets and credentials.
⤷ Title: HazyBeacon: Novel Backdoor Uses AWS Lambda for Stealthy C2, Targets Govts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:12:47 +0000
════════════════════════
⌗ Tags: #Malware #AWS Lambda #backdoor #C2 #Cloud Security #Command and Control #Cyberespionage #cybersecurity #DLL Sideloading #HazyBeacon #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:12:47 +0000
════════════════════════
⌗ Tags: #Malware #AWS Lambda #backdoor #C2 #Cloud Security #Command and Control #Cyberespionage #cybersecurity #DLL Sideloading #HazyBeacon #Unit 42
Daily CyberSecurity
HazyBeacon: Novel Backdoor Uses AWS Lambda for Stealthy C2, Targets Govts
Unit 42 uncovers HazyBeacon, a novel backdoor using AWS Lambda URLs for stealthy C2. It's deployed via DLL sideloading, targeting Southeast Asian govts for trade documents.
⤷ Title: CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:03:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Hijacking #CSRF #CVE_2025_43856 #cybersecurity #Immich #OAuth2 #open_source #Photo Management #Video Management #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:03:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Hijacking #CSRF #CVE_2025_43856 #cybersecurity #Immich #OAuth2 #open_source #Photo Management #Video Management #Vulnerability
Daily CyberSecurity
CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform
A flaw (CVE-2025-43856) in Immich allows account hijacking via a broken OAuth2 implementation (missing state parameter check). Update to v1.132.0 immediately!
⤷ Title: BlackSuit: New Royal/Conti Rebrand Hits With Speed, Stealth, & Data Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:00:30 +0000
════════════════════════
⌗ Tags: #Malware #BlackSuit #Cobalt Strike #Conti #Cybereason #cybersecurity #data exfiltration #PsExec #ransomware #Rclone #Royal Ransomware #threat actor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:00:30 +0000
════════════════════════
⌗ Tags: #Malware #BlackSuit #Cobalt Strike #Conti #Cybereason #cybersecurity #data exfiltration #PsExec #ransomware #Rclone #Royal Ransomware #threat actor
Daily CyberSecurity
BlackSuit: New Royal/Conti Rebrand Hits With Speed, Stealth, & Data Exfiltration
BlackSuit, a rebranded Royal/Conti ransomware, unleashes destructive multi-stage attacks. It uses Cobalt Strike, rclone for data exfil, and deletes shadow copies for stealth and speed.
⤷ Title: Two-Factor Authentication (2FA) Vulnerabilities: Full Analysis
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:22:06 GMT
════════════════════════
⌗ Tags: #penetration_testing #analysis #technology #vulnerability #bug_bounty
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:22:06 GMT
════════════════════════
⌗ Tags: #penetration_testing #analysis #technology #vulnerability #bug_bounty
Medium
Two-Factor Authentication (2FA) Vulnerabilities: Full Analysis
Inside the logic flaws, weak sessions, and social engineering tactics defeating multi-factor authentication today.
⤷ Title: Automation in Bug Bounty Hunting: Best Tools and Techniques
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:19:05 GMT
════════════════════════
⌗ Tags: #tips_and_tricks #penetration_testing #vulnerability #bug_bounty #technology
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:19:05 GMT
════════════════════════
⌗ Tags: #tips_and_tricks #penetration_testing #vulnerability #bug_bounty #technology
Medium
Automation in Bug Bounty Hunting: Best Tools and Techniques
Streamline Your Bug Hunting Workflow with the Best Automation Tools and Strategies
⤷ Title: How a 2FA Bypass Vulnerability in Drugs.com Exposed User Accounts
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:18:49 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #penetration_testing #hacking #tips_and_tricks
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:18:49 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #penetration_testing #hacking #tips_and_tricks
Medium
How a 2FA Bypass Vulnerability in Drugs.com Exposed User Accounts
Exposing a Critical Flaw in Authentication Security